PublicDateAtUSN: 2019-11-23 00:15:00 UTC Candidate: CVE-2019-11287 PublicDate: 2019-11-23 00:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11287 https://pivotal.io/security/cve-2019-11287 https://ubuntu.com/security/notices/USN-5004-1 Description: Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=945600 Priority: low Discovered-by: Assigned-to: leosilva CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_rabbitmq-server: upstream: https://github.com/rabbitmq/rabbitmq-server/pull/2155 upstream_rabbitmq-server: needs-triage precise/esm_rabbitmq-server: DNE trusty_rabbitmq-server: ignored (out of standard support) trusty/esm_rabbitmq-server: DNE xenial_rabbitmq-server: ignored (end of standard support, was needed) esm-infra/xenial_rabbitmq-server: released (3.5.7-1ubuntu0.16.04.4+esm1) bionic_rabbitmq-server: released (3.6.10-1ubuntu0.5) disco_rabbitmq-server: ignored (reached end-of-life) eoan_rabbitmq-server: ignored (reached end-of-life) focal_rabbitmq-server: not-affected (3.8.2-0ubuntu1.1) groovy_rabbitmq-server: not-affected (3.8.5-1) hirsute_rabbitmq-server: not-affected (3.8.9-1) impish_rabbitmq-server: not-affected (3.8.9-1) jammy_rabbitmq-server: not-affected (3.8.9-1) devel_rabbitmq-server: not-affected (3.8.9-1)